tcp ports comedy NOT

From: O'Brien, Pat <Pat.Obrien_at_choicepoint.com>
Date: Tue, 01 Apr 2003 10:38:36 -0500

I have discovered a checkpoint firewall bug whereas a reserved list of ports
for one tru 64 box can not be utilized by another. In other words, I have a
application on a system (system a) which has hardcoded ports identified
inside a firewall zone (zone a). When I ftp from a different system
(system b) in a different firewall zone ( zone b) to a third system (system
c) in a third zone (zone c), the return packet is assigned a random port
which by luck happens to be in the port range reserved on system a. Now
system b and c do not have this app, and do not care, but the firewall is
dropping the connect anyway. I am told this is a bug in our current version
of firewall software which is corrected in a more current version. Being
this upgrade is outside of my controll, my question is how to disable a
identifiable range of ports to prevent this issue which occurs most in ftp.
Received on Tue Apr 01 2003 - 15:39:27 NZST

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:44 NZDT